Description
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.
Published: 2026-08-13
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

File Browser versions before 2.63.22 do not validate access rules for descendant items during recursive copy, rename, or delete operations. This flaw allows an authenticated user to manipulate any file under an allowed parent directory, thereby bypassing path‑based access controls. The result is confidentiality and integrity violations of files that should have been protected.

Affected Systems

The vulnerability is present in File Browser deployment by the filebrowser vendor. All instances using versions earlier than 2.63.22 are affected, regardless of how the application is hosted or configured.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity. EPSS is not available, and the vulnerability is not currently listed in CISA KEV. Attackers need only authenticated credentials and are able to exploit the flaw by issuing standard recursive commands on a permitted parent directory; no additional privilege or network access beyond the application login is required.

Generated by OpenCVE AI on August 13, 2026 at 12:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade File Browser to version 2.63.22 or later.
  • If upgrading immediately is not feasible, restrict write permissions on parent directories and enforce stricter rule checks to prevent recursive operations on protected descendants.
  • Apply any vendor‑released patches or configuration changes that re‑establish proper access validation for recursive actions.

Generated by OpenCVE AI on August 13, 2026 at 12:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Filebrowser
Filebrowser filebrowser
Vendors & Products Filebrowser
Filebrowser filebrowser

Thu, 13 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Description File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based isolation for confidentiality and integrity.
Title File Browser before v2.63.22 Authorization Bypass via Recursive Operations
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Filebrowser Filebrowser
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-13T11:28:15.825Z

Reserved: 2026-08-13T11:16:27.834Z

Link: CVE-2026-73612

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T12:17:25.897

Modified: 2026-08-13T12:17:25.897

Link: CVE-2026-73612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T12:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key